FasterXML jackson-databind...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

## Jackson CVE-2019-12384: anatomy of a vulnerability class During one of our engagements, we analyzed an application which used the [Jackson](https://github.com/FasterXML/jackson) library for deserializing JSONs. In that context, we have identified a deserialization vulnerability where we could control the class to be deserialized. In this article, we want to show how an attacker may leverage this deserialization vulnerability to trigger attacks such as Server-Side Request Forgery (SSRF) and remote code execution. This research also resulted in a new [CVE-2019-12384](https://access.redhat.com/security/cve/cve-2019-12384) and a bunch of RedHat products affected by it: ![](https://images.seebug.org/1563868834855-w331s) ## What is required? As reported by Jackson’s author in [On Jackson CVEs: Don’t Panic — Here is what you need to know](https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062#da96) the requirements for a Jackson “gadget”...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息